Security Foundations
Malware & Attack Phases
Social Engineering & Physical
Web App Security
Network Security
100

What are the 3 core security principles.

What is confidentiality, integrity, and availability?

100

Malware disguised as a useful program, like a free PDF converter, that does not replicate itself.

What is a Trojan horse?

100

A phishing email crafted for one specific employee, using their name, job title, and current projects.

What is spear phishing?

100

Typing ' OR 1=1 -- into a login box is an attempt to manipulate the database behind the site with this attack.

What is SQL injection?

100

Cables, hubs, and electrical or radio signals belong to this OSI layer.

What is the Physical layer (Layer 1)?

200

A hurricane, a disgruntled employee, and a ransomware gang are all examples of this.

What is a threat?

200

Malware that secretly records keystrokes and browsing activity and reports them back to the attacker.

What is spyware?

200

A caller offers "free IT support" in exchange for your login credentials.

What is quid pro quo?

200

An attacker tries "Spring2026!" once against every account in the company to avoid triggering lockouts.

What is password spraying?

200

Video calls and online games often use this connectionless transport protocol because speed matters more than resending lost packets.

What is UDP?

300

In an IT security policy framework, these documents give step-by-step instructions for carrying out a policy.

What are procedures?

300

This virus type attaches itself to executable programs, such as .exe files.

What is a file infector?

300

An intruder slips through a secure door right behind an employee who never notices.

What is tailgating?

300

This cookie attribute helps prevent CSRF by limiting when the browser sends the cookie with cross-site requests.

What is SameSite?

300

This basic firewall type checks each packet's header against rules but keeps no memory of earlier packets.

What is packet filtering (stateless)?

400

A subset of AI that learn patterns from data and makes predictions without being explicitly programmed.

What is machine learning?

400

This virus classification rewrites its own code with each infection to evade signature-based antivirus.

What is a polymorphic virus?

400

Name the physical control type for each: a motion-activated alarm, bright exterior lighting, a locked server-room door.

What are detective, deterrent, and preventive?

400

Converting characters like < and > into harmless HTML entities before displaying user content is this XSS defense.

What is output encoding?

400

Name the protocol that uses each port: 22, 25, 53, 443.

What are SSH, SMTP, DNS, and HTTPS?

500

What are the 7 domains of an IT Infrastructure?

What are the User, Workstation, LAN, LAN-to-WAN, WAN, Remote Access, and System/Application.

500

Put these attacker actions in phase order and name which phase they correspond to: deleting log files, scanning ports, installing a backdoor, exploiting an unpatched web server.

What are scanning ports (Reconnaissance), exploiting the server (Gaining Access), installing a backdoor (Maintaining Access), and deleting logs (Covering Tracks)?

500

This security strategy uses layered security controls.

What is defense in depth?

500

This attack injects malicious JavaScript into a trusted web page so it runs in other visitors' browsers.

What is cross-site scripting (XSS)?

500

Match a tool to each problem: (a) a visitor plugs an unknown laptop into a conference-room jack, (b) a sales rep needs the internal CRM from a hotel, (c) the public web server must be isolated from internal systems, (d) guest devices and accounting systems share switches but must not share traffic.

What are (a) NAC, (b) a remote-access VPN, (c) a screened subnet (DMZ), and (d) VLANs?